Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

Project Subscriptions

Vendors Products
Mattermost Subscribe
Mattermost Subscribe
Mattermost Server Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4305 Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
Github GHSA Github GHSA GHSA-rhvr-6w8c-6v7w Mattermost fails to invalidate all active sessions when converting a user to a bot
Fixes

Solution

Update Mattermost to versions 10.5.0, 9.11.7, 10.4.2 or higher.


Workaround

No workaround given by the vendor.

References
History

Wed, 01 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Mon, 24 Feb 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 07:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
Title Session Persistence After User-to-Bot Conversion
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-02-24T11:23:35.862Z

Reserved: 2025-02-18T11:59:15.633Z

Link: CVE-2025-1412

cve-icon Vulnrichment

Updated: 2025-02-24T11:23:30.150Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-24T08:15:09.890

Modified: 2025-10-01T18:02:32.873

Link: CVE-2025-1412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:25Z

Weaknesses